# streaak/keyhacks

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

Repository: https://github.com/streaak/keyhacks
Canonical: https://ross.abutalabs.com/products/keyhacks
License Family: other
Last push: 2026-08-07T07:14:53+00:00

## Health v2 (maintenance only)
Score: 75/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 96, release rhythm 35, longevity 100
- inputs: {"age_days": 2731, "days_push": 26, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 6322, forks 1225 (observed 2026-08-28T04:09:41.751916+00:00)

## What it is
KeyHacks is a curated reference repository listing commands and methods to validate leaked API keys found during bug bounty programs or penetration tests. It covers dozens of services (AWS, GitHub, Slack, MailGun, etc.) with quick checks for whether a key is valid.

## Use cases
- validate leaked api keys found in a pentest
- check if an aws access key found in a bug bounty is valid
- test whether a github token is active
- verify slack or mailgun api keys during recon
- learn how to test leaked credentials safely

## When to choose
- you are doing bug bounty or penetration testing and found exposed API keys
- you need quick, copy-paste validation commands for many SaaS services
- you want a reference of API key formats and test endpoints

## When to avoid
- you need an automated scanner rather than a manual reference
- you are looking for a tool to crack or brute-force credentials
- you need production security tooling with support and licensing

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, osint, developer-tools
- domain: security, penetration-testing, developer-tools
- platform: cli, cross-platform
- tags: bug-bounty, api-key-validation, pentest, cheatsheet, leaked-credentials

## Member repositories
- streaak/keyhacks (main) score 75

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:41.751916+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:46:11.174264+00:00, confidence not recorded.
  - readme: https://github.com/streaak/keyhacks (fetched 2026-08-28T04:09:41.751916+00:00, sha 72c2634f6b7c)
- Data as of 2026-08-30T08:39:29.467469+00:00.
